Senior Engineer, GRC – Audit & Compliance

Job not on LinkedIn

🕒 May 22

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of NextGen Healthcare

NextGen Healthcare

1001 - 5000 employees

Founded 1998

⚕️ Healthcare Insurance

☁️ SaaS

📡 Telecommunications

💰 Venture Round on 2015-02

Healthcare Insurance • SaaS • Telecommunications

NextGen Healthcare is a company that provides integrated health IT solutions to ambulatory practices. Their services include electronic health records (EHR), practice management, interoperability, patient engagement, and telehealth solutions. They aim to enhance the patient and provider experience through innovative technologies such as AI-driven workflows and mobile solutions. NextGen Healthcare also offers tailored solutions for various specialties and focuses on improving clinical and financial outcomes for their clients. They support practices of all sizes, from small offices to large enterprises, and emphasize the importance of interoperability and data exchange to enhance healthcare delivery.

📋 Description

• Responsible for leading the organization’s audit and compliance programs, ensuring continuous alignment with regulatory, contractual, and security framework requirements. • Owns the end-to-end audit lifecycle, including planning, readiness, evidence management, auditor coordination, and remediation tracking across frameworks such as SOC 2, HITRUST, PCI DSS, HIPAA, and NIST CSF. • Act as the primary liaison between internal stakeholders and external auditors, ensuring audit readiness and sustained compliance posture. • Operates as a senior individual contributor responsible for driving compliance execution, maintaining control frameworks, and leveraging GRC tools to enable scalable and efficient compliance operations. • Leverage tools and technology to support Information Security audit, compliance, and GRC initiatives across the Information Security Program • Act as system administrator for certain security or GRC tools such as phishing and training platforms, GRC/IT Risk Management tools, Third Party Risk Management (TPRM) platforms, Risk Register, privacy management, etc. • Integrate related tools and workflows with other systems as needed. • Engage with internal stakeholders and security vendors on design sessions, and help configure and optimize GRC solutions and compliance workflows. • Work with IT partners in Application Security, Security Engineering and Operations, Enterprise Applications, Desktop Support, Help Desk, Networking and Infrastructure Operations, to get data and information needed to support GRC work and audit & compliance activities. • Collaborate with IT teams and Information Security teams to obtain security and operational data needed to support audit, compliance, and risk assessment activities. • Work with IT teams and partners to align GRC objectives with enterprise security controls and operational processes including cybersecurity / technology solutions such as IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPS, XDR, MDM, SIEM, etc. • Support data analysis, metrics, dashboards and reporting activities by pulling data from source systems. • Stay current with evolving regulatory requirements, compliance frameworks, industry trends, threat intelligence and make recommendations for process and control improvements. • Participate in security incidents and support related audit, compliance and remediation activities as needed. • Support security assessment requests for customers, HITRUST, SOC 2, etc. by pulling appropriate data as needed. • Work with IT partners to align GRC requirements with operational processes such as secure software development life cycle, software engineering, infrastructure, network, etc. • Maximize the utilization of GRC tools and technology to improve program efficiency and audit readiness • Assist with the development and maintenance of policies, procedures and compliance documentation. • Stay current with changes in information security and cybersecurity regulations, industry frameworks, and best practices, and apply them to existing NextGen GRC solutions and processes. • Use GRC and security engineering skills to help streamline or automate NextGen methodology for maintaining accreditations or certifications (e.g., SOC 2, HITRUST, etc.). • Use GRC and security engineering skills to help streamline or automate NextGen methodology for responding to customer security assessments or questionnaires.

🎯 Requirements

• Bachelor's Degree in Computer Science or related discipline or advanced degree. • 4-6 years of relevant experience or advanced Degree. • GRC/Security engineering experience, including supporting information security or cybersecurity solutions. • Experience working with security technology, GRC tools, or processes such as phishing campaigns, vulnerability scans, IRPs, playbooks, IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPS, XDR, MDM, SIEM, threat hunting, etc. • Experience with one or more of the following frameworks: COSO, NIST CSF, RMF, ISO, COBIT. • Experience working in an environment with one or more of the following: Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), AICPA System and Organization Controls 2(SOC 2) , Payment Card Industry (PCI), or related GRC frameworks • Information security or cybersecurity related certifications such as CISA, CISSP, CISM, CRISC, CEH, GIAC (GCFA), or ability to acquire certification within 18 months. • HITRUST Framework and CSF certification knowledge. • IT / security processes or tools such as IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPS, XDR, MDM, SIEM, IRP, backups, DR & BCP, playbooks, MSP or MSSP, MDR or XDR, 24x7 SOC, endpoint security, SIEM, vulnerability scans, patching, pen testing, red/blue/purple teaming, tabletop exercises, encryption at rest and in transit, networking, firewalls, infrastructure, colo data centers, hosted environments such as Azure, AWS, or Google Cloud, and Active Directory.

🏖️ Benefits

• Benefits includes health insurance, retirement plans, paid time off, flexible work arrangements, professional development opportunities, bonuses, stock options, equipment allowances, wellness programs

Apply Now

Similar Jobs

🕒 May 22

Twilio

5001 - 10000

Strategy & Operations role focusing on telecommunications compliance at Twilio. Leading strategic execution and governance for global communications platform compliance initiatives.

🕒 May 21

Nuvei

1001 - 5000

💳 Fintech

🛍️ eCommerce

🎮 Gaming

Compliance Officer managing AML and BSA compliance programs at a global fintech company. Leading compliance efforts in North America amidst evolving payment processing regulations.

🇺🇸 United States – Remote

💰 $500M Post-IPO Secondary on 2021-05

⏰ Full Time

🟡 Mid-level

🟠 Senior

🚔 Compliance

🗣️🇫🇷 French Required

🕒 May 21

Integrity Management Services, Inc.

51 - 200

📋 Compliance

🏛️ Government

🎯 Recruiter

Specialist conducting audits on Medicaid Managed Care Plans to identify fraud, waste, and abuse while ensuring regulatory compliance. Reporting findings and working collaboratively with auditing staff.

🕒 May 21

Airbnb

5001 - 10000

👥 B2C

🛍️ eCommerce

Senior Regulatory Operations Manager driving regulatory compliance strategies across jurisdictions for Airbnb. Leading initiatives with cross-functional teams to ensure successful execution and project alignment.

🕒 May 21

Cushman & Wakefield

10,000+ employees

🏠 Real Estate

🏢 Enterprise

Facility Compliance Analyst focusing on compliance programs across multi-site facilities portfolio. Supporting audit readiness, operational assessments, and compliance documentation governance.